MAL-2026-16071

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16071
Published
2026-09-09T05:33:44Z
Modified
2026-09-16T01:15:05Z
Summary
Malicious code in cat-sis2go-utils (npm)
Details

cat-sis2go-utils is a dependency-confusion package published against the SIS2GO namespace, with versions inflated to 99.0.0 and 99.1.0. It ships no library code (index.js is an 87-byte stub), and package.json declares both preinstall and postinstall running node scripts/run.js, so the payload executes twice during npm install before any application code. The script resolves a DNS canary and POSTs to a webhook.site collector; 99.1.0 additionally sends os.userInfo().username and os.hostname(). The author labels this a PoC, but the beacon fires on any install that resolves the package and exfiltrates a username usable for follow-on attacks, and dependency-confusion packages require incident response even when trivial.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91)

Package cat-sis2go-utils@99.0.0 declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control.

Database specific
{
    "iocs":  {
        "domains":  [
            "d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site"
        ],
        "files":  [
            {
                "digests":  {
                    "sha256":  "0897440200959313ca1e8735d8d1524f70a0bddcde66778ecd46c0bb4981981f"
                },
                "note":  "Present in versions 99.0.0 and 99.1.0.",
                "paths":  [
                    "index.js"
                ],
                "source":  "PACKAGE_ARCHIVE"
            },
            {
                "digests":  {
                    "sha256":  "91b460b9612ce51d74cb187bcf1793bd115255b117e5ca5858075c3a90b6b2b9"
                },
                "note":  "Present in version 99.0.0.",
                "paths":  [
                    "package.json"
                ],
                "source":  "PACKAGE_ARCHIVE"
            },
            {
                "digests":  {
                    "sha256":  "b0ccdc7aaba664b0b4da3f317d06789d4cda2473f50c37a1c13264389130d6d7"
                },
                "note":  "Present in version 99.0.0.",
                "paths":  [
                    "scripts/run.js"
                ],
                "source":  "PACKAGE_ARCHIVE"
            },
            {
                "digests":  {
                    "sha256":  "0e3e6be9b193ff4b3e6bd60bc0bfe1d97b9f1c2d73d8fa2d731597b00b8501c1"
                },
                "note":  "Present in version 99.1.0.",
                "paths":  [
                    "package.json"
                ],
                "source":  "PACKAGE_ARCHIVE"
            },
            {
                "digests":  {
                    "sha256":  "0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b"
                },
                "note":  "Present in version 99.1.0.",
                "paths":  [
                    "scripts/run.js"
                ],
                "source":  "PACKAGE_ARCHIVE"
            }
        ],
        "urls":  [
            "https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7"
        ]
    },
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-019843",
            "import_time":  "2026-09-09T05:40:09.19538336Z",
            "modified_time":  "2026-09-09T05:33:44Z",
            "sha256":  "205b59e55b3e3474f6b5de7471c11e7095e019a9f1e682083b34eeb7dddd5c3f",
            "source":  "amazon-inspector",
            "versions":  [
                "99.1.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-019845",
            "import_time":  "2026-09-09T05:40:09.252208812Z",
            "modified_time":  "2026-09-09T05:34:00Z",
            "sha256":  "ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / cat-sis2go-utils

Package

Name
cat-sis2go-utils
View open source insights on deps.dev
Purl
pkg:npm/cat-sis2go-utils

Affected ranges

Affected versions

99.*
99.0.0
99.1.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "scripts/run.js",
            "sha256":  "0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b",
            "tlsh":  "952103e648f581281ef342c0574bec5aa273da067546ee9076ac03321fc59fc9a739f8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "cat-sis2go-utils-99.1.0.tgz",
            "hashes":  {
                "sha1":  "49e87faf015f6773e543b29044c7ee396b20c85f",
                "sha512_sri":  "sha512-wx8JSI0n1stzrdeP3eUD9piuGQKVMbrB4/ZV/Ez1IaNUT+4EBXSmejvY64wx7xd9dQ43x60XN4i3msVUW3dr6A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json"